fix: code cleanup — path traversal, test leaks, dead code, consistency

- Add path traversal protection to GET /api/cases/:name and fix-plan
- Use safePathSchema for LinkCaseSchema.path
- Fix QR auth test timer leak (afterAll → afterEach) and env var try/finally
- Remove dead terminal size check after Zod validation in resize route
- Remove no-op sampleCount guard in adaptive timing
- Replace hardcoded values with constants in notification-manager and subagent-windows
- Add Zod validation to POST /api/auth/revoke
- Use _apiPut instead of raw fetch in subagent-windows
- Add SwipeHandler.cleanup() for consistency with other mobile handlers
- Move NiceConfig/ProcessStats from types/plan.ts to types/common.ts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-03-01 17:26:31 +01:00
co-authored by Claude Opus 4.6
parent f94ab08cbe
commit d094d9ec50
11 changed files with 94 additions and 71 deletions
+6 -6
View File
@@ -188,9 +188,9 @@ class NotificationManager {
count: 1,
};
// Add to log (cap at 100)
// Add to log (cap at NOTIFICATION_LIST_CAP)
this.notifications.unshift(notification);
if (this.notifications.length > 100) this.notifications.pop();
if (this.notifications.length > NOTIFICATION_LIST_CAP) this.notifications.pop();
// Track for grouping
const timeout = setTimeout(() => this.groupingMap.delete(groupKey), GROUPING_TIMEOUT_MS);
@@ -298,9 +298,9 @@ class NotificationManager {
}
if (Notification.permission !== 'granted') return;
// Rate limit: max 1 per 3 seconds
// Rate limit
const now = Date.now();
if (now - this.lastBrowserNotifTime < 3000) return;
if (now - this.lastBrowserNotifTime < BROWSER_NOTIF_RATE_LIMIT_MS) return;
this.lastBrowserNotifTime = now;
const notif = new Notification(`Codeman: ${title}`, {
@@ -318,8 +318,8 @@ class NotificationManager {
notif.close();
};
// Auto-close after 8s
setTimeout(() => notif.close(), 8000);
// Auto-close
setTimeout(() => notif.close(), AUTO_CLOSE_NOTIFICATION_MS);
}
async requestPermission() {